Jump to content

Recommended Posts

Posted

I have a question about how Bitlocker works, specifically on Windows 10. There is enough on the internet to explain the basics but I'm struggling to find really clear answers on the below... Would really appreciate any advice you guys can give!

I recently decided to protect the single (SSD) hard drive in my Windows 10 laptop with Bitlocker. I have a TPM (Trusted Platform Module), so chose that option, the setup & encyption process was simple enough, and I've not had any problems with it since.

I understand the basics of how the TPM module works, checking key OS files/configuration parameters etc. are unchanged before releasing the keys to decrypt the rest of the drive/complete the boot into Windows. I understand how this then protects the data on the hard drive if it's ever removed from my laptop.

 

My understanding is that the TPM decrypts just enough to allow Windows to boot and prompt you for a password, and entering this then decrypts the remainder of the drive... so does this mean the data on the Bitlocker protected drive is then only protected by my Windows password if the whole laptop is stolen? Does using a fingerprint or some other method make any difference?

 

Secondly, on my laptop, I realised my wife's own user account actually had no password set when I enabled Bitlocker, so in this case, there would have been no protection of my data at all if the entire laptop had been stolen!? I've since made her set a password, but due to my lack of understanding of the previous, I now I have lingering doubts about whether this might have compromised my Bitlocker setup & effectiveness.

Posted

There is a bit more information here BitLocker Drive Encryption Overview

 

The laptop reading the TMP and encryption key it holds is invisible to the user. Bitlocker encrypts whole partitions not just part of the data.

This stops the usual tricks of blanking the Windows password and also makes reading the drive in another computer impossible unless you have a copy of the Bitlocker key.

 

If you want to check, remove the hard drive and add it as a slave to another computer.

Posted
Thanks for the clarification difinity - I had read that link but it seems to have been written for Windows Vista, and I didn't know if anything about how Bitlocker works had changed in Windows 10
Posted

I'm moving over to Bitlocker from Sophos Safeguard (for new devices and re-builds) and would like to sanity check a few of the decisions I'm making:

 

I want to use Transparent Mode with TPM - would you consider this secure enough if I get challenged/to be able to sleep at night when a device is lost?

Do I need to set BIOS passwords for this approach?

I am storing the recovery information in AD and preventing users from taking their own backups, as I don't trust them to keep the information sufficiently secure - is that asking for trouble?

I am preventing them from setting PINs or passwords or using USB keys, as I want consistency in case I have to recover them or we require the devices to be used by multiple users.

I can't afford MBAM, but intend to use the Sophos Enterprise console to manage Bitlocker - mostly so that I have evidence of the status of the devices. Will this cause any problems with using Group Policies for settings?

Can I use Sophos to start the encryption process or do I need to do this on each machine? (Machines are built and I didn't set the options in WDS)

 

Answers to any of the questions greatly appreciated :D

 

Thanks all

Posted
I'm moving over to Bitlocker from Sophos Safeguard (for new devices and re-builds) and would like to sanity check a few of the decisions I'm making:

 

I want to use Transparent Mode with TPM - would you consider this secure enough if I get challenged/to be able to sleep at night when a device is lost?

Do I need to set BIOS passwords for this approach?

I am storing the recovery information in AD and preventing users from taking their own backups, as I don't trust them to keep the information sufficiently secure - is that asking for trouble?

I am preventing them from setting PINs or passwords or using USB keys, as I want consistency in case I have to recover them or we require the devices to be used by multiple users.

I can't afford MBAM, but intend to use the Sophos Enterprise console to manage Bitlocker - mostly so that I have evidence of the status of the devices. Will this cause any problems with using Group Policies for settings?

Can I use Sophos to start the encryption process or do I need to do this on each machine? (Machines are built and I didn't set the options in WDS)

 

Answers to any of the questions greatly appreciated :D

 

Thanks all

 

In this case your encryption is only as strong as your Windows password IMO. Yes your laptop is 100% fully encrypted and if the drive is put in another machine it won't be readable, but if the Windows password is 1234 that doesn't stop someone from simply guessing it. We deploy BitLocker in our school with forced PINs. This way users must enter their 8 digit PIN code before Windows will boot past BitLocker.

 

I can't answer any of your Sophos related questions, but MDOP MBAM is now included as part of the Windows licensing on Windows 10 and above. Maybe this makes it more affordable for you?

  • Thanks 1
Posted

 

I can't answer any of your Sophos related questions, but MDOP MBAM is now included as part of the Windows licensing on Windows 10 and above. Maybe this makes it more affordable for you?

 

Still had MDOP on the list of things that I thought should be included in EES but wasn't....

 

Installing MBAM now :D

Posted

So now I'm playing with MBAM....

 

It seems that I need a full version of SQL Server, which if I understand correctly is something that I would need to pay for. Have I got the wrong end of the stick or does this "free" offering have a cost implication after all? Or is it included in something I'm missing?

 

Thanks again.

Posted

I'm still struggling with this. I've configured a GPO (images attached) which essentially is intended to force backup of the recovery key to AD and prevent users saving it. Another key setting from my point of view is that I've enabled the "Omit recovery options from the BitLocker setup wizard", which I would expect to do just that. I've set it to prevent the users creating a password or PIN. However when I go to "Turn on BitLocker" in the control panel on the client, I get the error message "You can't create both a recovery password and a recovery key". The other thing I've done is configured the permissions on the DC to allow computer objects to write to themselves - which I presume is necessary to write the Recovery Key to the object.

 

Bitlocker Policy 1.JPG

Bitlocker Policy 2.JPG

 

I did wonder if I've borked this... As above, I started with MBAM and I know that if I'm using that to manage Bitlocker I need to leave the Bitlocker Drive Encryption GPO settings alone and configure them in the (imported) MDOP MBAM ADMX. However, I can't use MBAM because I don't have SQL Server, so I'm back to configuring the standard GPO. What I've noticed is that when I configure settings there, the settings are also changed in the MDOP MBAM section - could this be causing a conflict? And if so, can you get rid of ADMX templates from the central store?

 

Thanks in advance...

  • 2 weeks later...
Posted

Hi all

 

I'm getting slightly different error messages now, but am no further forward..........

 

I still have the "Omit recovery options" policy enabled, but I get the prompt "How do you want to back up your recovery key?" and have the options "Save to a file" and "Print the recovery key". However when I try and select either I get the error message "Your recovery key couldn't be saved to this location". I have now enabled users to save their recover information, but no change. Any ideas? I'm stuck again now.

 

The other query I have is that when I start the process, Windows creates a new hidden partition (there isn't a recovery partition in my build) which in Disk Management is labelled as Recovery Partition. I can't do anything with it in the GUI, but from Diskpart.exe, I can see that it is correctly formatted as NTFS. Do I need to do anything else to create this drive or will Bitlocker take care of it?

 

Thanks again :)

  • 1 month later...
Posted

So I'm still playing with this and only have partial success :Cry:

 

The good news: The drives encrypt as required using the item on the Control Panel.

 

The bad news - most of the rest of the policy seems to fail - I can't prevent users from storing the recovery key and I can't persuade it to store the key in AD

 

My plan was to set it up as administrator and then restrict access to the relevant areas in Control Panel using GPO. About half way through, I no longer get the option to print or save the recovery key, so I thought I'd retrieve it from command line. I'm using manage-bde -protectors C: -get

This returns All Key Protectors and shows the TPM ID in the expected format, but no passwords. I also tried manage-bde -protectors C: -get -type RecoveryPassword and I get "ERROR: No key protectors found.

 

I'm not locked out (yet!) but surely there must be a way of recovering it if I needed to? er.. Help?

 

Thanks as always

Posted
So I'm still playing with this and only have partial success :Cry:

 

The good news: The drives encrypt as required using the item on the Control Panel.

 

The bad news - most of the rest of the policy seems to fail - I can't prevent users from storing the recovery key and I can't persuade it to store the key in AD

 

My plan was to set it up as administrator and then restrict access to the relevant areas in Control Panel using GPO. About half way through, I no longer get the option to print or save the recovery key, so I thought I'd retrieve it from command line. I'm using manage-bde -protectors C: -get

This returns All Key Protectors and shows the TPM ID in the expected format, but no passwords. I also tried manage-bde -protectors C: -get -type RecoveryPassword and I get "ERROR: No key protectors found.

 

I'm not locked out (yet!) but surely there must be a way of recovering it if I needed to? er.. Help?

 

Thanks as always

 

I assume like the OP you're using Windows 10? and that you are also using MBAM 2.5 with the new MBAM 2.5 client on the device?

Posted
I assume like the OP you're using Windows 10? and that you are also using MBAM 2.5 with the new MBAM 2.5 client on the device?

Windows 10 education, but not MBAM. Whilst MBAM is free with our MS agreement, from the instructions I read, you need a full version of SQL server running to make it work and I don't have a licence for that.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...